Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
Jizhicms MEDIUM 5.3
CVE-2025-2638

A vulnerability, which was classified as problematic, was found in JIZHICMS up to 1.7.0. This affects an unknown part of the file /user/release.html …

Fix: after 1.7
Fix from $1,600 2025-03-23
Jizhicms MEDIUM 5.3
CVE-2025-2637

A vulnerability, which was classified as problematic, has been found in JIZHICMS up to 1.7.0. Affected by this issue is some unknown functionality of…

Fix: after 1.7
Fix from $1,600 2025-03-23
Next.js CRITICAL 9.1
CVE-2025-29927EPSS 99%

Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and …

Fix: 12.3.5 / 13.5.9+
Fix from $2,300 2025-03-21
Human Resource Management CRITICAL 9.8
CVE-2025-2589

A vulnerability was found in code-projects Human Resource Management System 1.0.1 and classified as critical. This issue affects the function Index o…

No fix yet
Fix from $2,300 2025-03-21
Unclassified CRITICAL 9.6
CVE-2025-29922

kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.26.3, the identified vuln…

Patch available
Fix from $2,300 2025-03-20
Xwiki CRITICAL 9.8
CVE-2025-29926

XWiki Platform is a generic wiki platform. Prior to 15.10.15, 16.4.6, and 16.10.0, any user can exploit the WikiManager REST API to create a new wiki…

Fix: 15.10.15 / 16.4.6+
Fix from $2,300 2025-03-19
Dr 820 Firmware HIGH 7.3
CVE-2025-30117

An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Managing Settings and Obtaining Sensitive Data and Sabotaging the Car Batt…

Mitigation only
Fix from $1,950 2025-03-18
Tastyigniter MEDIUM 6.5
CVE-2024-44314

TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the Orders Management System, allowing unauthorized users to update order st…

Mitigation only
Fix from $1,600 2025-03-18
Dir 823g Firmware CRITICAL 9.8
CVE-2025-2360

A vulnerability classified as critical was found in D-Link DIR-823G 1.0.2B05_20181207. Affected by this vulnerability is the function SetUpnpSettings…

No fix yet
Fix from $2,300 2025-03-17
Dir 823g Firmware CRITICAL 9.8
CVE-2025-2359EPSS 15%

A vulnerability classified as critical has been found in D-Link DIR-823G 1.0.2B05_20181207. Affected is the function SetDDNSSettings of the file /HNA…

No fix yet
Fix from $2,300 2025-03-17
Unclassified CRITICAL 9.8
CVE-2025-2345

A vulnerability, which was classified as very critical, was found in IROAD Dash Cam X5 and Dash Cam X6 up to 20250308. This affects an unknown part. …

Mitigation only
Fix from $2,300 2025-03-16
Springboot Openai Chatgpt CRITICAL 9.8
CVE-2025-2320

A vulnerability has been found in 274056675 springboot-openai-chatgpt e84f6f5 and classified as critical. Affected by this vulnerability is the funct…

No fix yet
Fix from $2,300 2025-03-14
Dataverse HIGH 7.2
CVE-2025-24053

Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $1,950 2025-03-13
Umbraco Cms MEDIUM 6.4
CVE-2025-27602

Umbraco is a free and open source .NET content management system. In versions of Umbraco's web backoffice program prior to versions 10.8.9 and 13.7.1…

Fix: 10.8.9 / 13.7.1+
Fix from $1,600 2025-03-11
Unclassified CRITICAL 9.3
CVE-2025-27509

fleetdm/fleet is an open source device management, built on osquery. In vulnerable versions of Fleet, an attacker could craft a specially-formed SAML…

Patch available
Fix from $2,300 2025-03-06
Aqt1000 Firmware MEDIUM 5.5
CVE-2024-43051

Information disclosure while deriving keys for a session for any Widevine use case.

No fix yet
Fix from $1,600 2025-03-03
Zz HIGH 8.8
CVE-2025-1847

A vulnerability was found in zj1983 zz up to 2024-8. It has been rated as critical. This issue affects some unknown processing. The manipulation lead…

Fix: after 2024-8
Fix from $1,950 2025-03-03
Unclassified HIGH 7.3
CVE-2025-1815

A vulnerability, which was classified as critical, was found in pbrong hrms up to 1.0.1. This affects the function HrmsDB of the file \resource\resou…

Mitigation only
Fix from $1,950 2025-03-02
Mastodon MEDIUM 5.3
CVE-2025-27399

Mastodon is a self-hosted, federated microblogging platform. In versions prior to 4.1.23, 4.2.16, and 4.3.4, when the visibility for domain blocks/re…

Fix: 4.1.23 / 4.2.16+
Fix from $1,600 2025-02-27
Mautic HIGH 7.7
CVE-2024-47053

This advisory addresses an authorization vulnerability in Mautic's HTTP Basic Authentication implementation. This flaw could allow unauthorized acces…

Fix: 5.2.3+
Fix from $1,950 2025-02-26
Country Blocker MEDIUM 5.3
CVE-2025-1361

The IP2Location Country Blocker plugin for WordPress is vulnerable to Regular Information Exposure in all versions up to, and including, 2.38.8 due t…

Fix: 2.38.9+
Fix from $1,600 2025-02-22
Helm Charts CRITICAL 9.8
CVE-2025-25196

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA < v1.8.4 (He…

Fix: 0.2.22 / 1.8.5+
Fix from $2,300 2025-02-19
Open Vsx MEDIUM 5.3
CVE-2025-1007

In OpenVSX version v0.9.0 to v0.20.0, the /user/namespace/{namespace}/details API allows a user to edit all namespace details, even if the user is …

Fix: 0.19.1+
Fix from $1,600 2025-02-19
Return Refund And Exchange For Woocommerce MEDIUM 5.4
CVE-2024-13692

The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Features plugin for WordPress is vul…

Fix: 4.4.6+
Fix from $1,600 2025-02-14
Yimioa CRITICAL 9.8
CVE-2025-1226

A vulnerability was found in ywoa up to 2024.07.03. It has been declared as critical. This vulnerability affects unknown code of the file /oa/setup/s…

Fix: 2024-07-04+
Fix from $2,300 2025-02-12
Booking Calendar MEDIUM 5.3
CVE-2024-13821

The WP Booking Calendar plugin for WordPress is vulnerable to Unauthenticated Post-Confirmation Booking Manipulation in all versions up to, and inclu…

Fix: 10.10.1+
Fix from $1,600 2025-02-12
Commerce B2b HIGH 8.1
CVE-2025-24418

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Authorization vulnerability tha…

Fix: 1.3.3+
Fix from $1,950 2025-02-11
Sharepoint Server HIGH 8.0
CVE-2025-21400EPSS 34%

Microsoft SharePoint Server Remote Code Execution Vulnerability

Fix: 16.0.17928.20396+
Fix from $1,950 2025-02-11
Unclassified MEDIUM 5.3
CVE-2025-1078

A vulnerability has been found in AppHouseKitchen AlDente Charge Limiter up to 1.29 on macOS and classified as critical. This vulnerability affects t…

Mitigation only
Fix from $1,600 2025-02-06
Harmonyos HIGH 7.5
CVE-2024-57954

Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidenti…

No fix yet
Fix from $1,950 2025-02-06